Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CMMC POA&M rules infographic

CMMC POA&M Rules: The Essential 2026 Guide to Conditional Level 2 Status

The CMMC POA&M rules decide whether a defense contractor with a few open gaps can still earn a conditional Level 2 status or must fix everything before an assessment. Many companies plan around the idea that a plan of action and milestones lets them defer the hard controls, and then find out too late which ones cannot be deferred.

This guide explains the published rules: the minimum score, the closeout window, what the plan must contain, which kinds of requirements cannot be placed on it and how the 2026 changes to the program timeline affect your planning. It is written for contractors handling controlled unclassified information. Rules are set by the Department of Defense rulemaking and contract clauses and can change, so check the current text and your contract before relying on any figure below.

Free gap assessment

What is your CMMC Level 2 readiness, really?

Score all 110 practices, free, plus the scoping and POA&M questions that decide whether your SPRS score is usable.

Run the free CMMC gap assessment →  or  View premium report sample

What the CMMC POA&M rules allow

A plan of action and milestones, or POA&M, is a document that lists requirements you have not yet met, what you will do about them, who owns the work and when it will be done. Under the published CMMC Level 2 rules, a contractor can receive a conditional status if it achieves a minimum score and documents the remaining gaps in a POA&M, then closes them within a fixed window.

Summaries of the current rules report that the minimum score is 88 out of 110 points, which is 80 percent, and that unmet requirements must be fully remediated within 180 days. Below that score, neither a POA&M nor conditional status is available, and the contractor must fix gaps before it can be certified. Read our overview of CMMC compliance for the broader program.

Which requirements cannot be put on a POA&M

The rules do not let you defer everything. Commentary on the published rule reports that requirements worth more than one point in the scoring methodology cannot be deferred, and that a short list of specific requirements is excluded regardless of score. One summary says those include the system security plan requirement, which means that you cannot go into an assessment without a plan and expect to fix it later. The same summary lists certain physical protection and external connection requirements as excluded.

Because the detailed list comes from the rule text and scoring methodology, verify it against the current regulation and assessment guide before finalizing your plan. Do not rely on any summary, including this one, for the boundary between what can and cannot be deferred. Our guide to the NIST 800-171 SSP explains why the plan must be complete.

How the 88-point threshold works in practice

Each requirement carries a point value in the scoring methodology, and every unmet requirement subtracts its value from 110. To reach 88, you can miss at most 22 points, which in practice means that your gaps must be limited to low-value items. A single unmet five-point requirement uses almost a quarter of your margin and cannot be placed on a POA&M anyway, so heavy items must be solved first.

Run an honest internal scoring exercise before booking anything. Use the assessment objectives, not your impression of your environment, and ask an independent person to review the result. If your score sits just above the threshold, treat it as below until you have fixed the borderline items, because assessors can disagree with your self-score.

RuleWhat is reportedPlanning consequence
Minimum scoreAt least 88 of 110 points to use a POA&MBelow the threshold, all gaps must be fixed before assessment
StatusMeeting the threshold can lead to a conditional Level 2 statusConditional is temporary, not final
CloseoutOpen items must be remediated within 180 daysSchedule fixes and reassessment early
Level 1POA&Ms are not permittedAll Level 1 practices must be met
Excluded itemsHigher-value and some specific requirements cannot be deferredFix these first
System security planThe plan itself cannot be deferredWrite it before you book an assessment

Writing a POA&M that stands up

A useful POA&M has one row per open requirement with the requirement number, a plain description of the gap, the planned fix, the owner, the start date, the target date, the status and the evidence that will show closure. Keep target dates realistic and well inside the 180-day window, leaving time for a reassessment.

Avoid vague actions such as improve monitoring. State what will change: deploy a tool, write and approve a procedure, train named staff, or migrate a system. Link each row to the implementation statements in your plan so the two documents agree. The SPRS score you report should reflect the same gaps.

Conditional status and the 180-day closeout

Conditional status is a clock, not a finish line. After the assessment, you must close the open items and have them confirmed within the window or the status lapses. Plan the closeout work before the assessment starts: make sure budget, tools and people are allocated so that fixes are not waiting on procurement cycles.

Coordinate with the assessor about how closeout verification will work. Ask what evidence it needs and how it will be submitted, and build that into the plan. Our page on the C3PAO role explains how assessment organizations operate, and CMMC scoping explains how a smaller boundary can shrink both the gaps and the cost.

What the 2026 timeline changes mean

The phased rollout began on 10 November 2025 with self-assessment requirements, and the next phase, involving third-party assessments, was originally due on 10 November 2026. Reporting from a defense compliance publication states that on 13 July 2026 the Department of War CIO suspended that second phase and pending future milestones pending a reform review, and that no replacement date had been announced as of late September 2026. Another published summary reports the same suspension. Confirm the present status with official sources.

Practically, self-assessments, annual affirmations and accurate SPRS records remain required where your contracts call for them, and the underlying NIST SP 800-171 requirements have not changed. Your actual deadline depends on your contract language, so ask your contracting officer or prime. See CMMC Phase 2 for our earlier coverage, which you should read alongside the latest status.

A practical plan for the CMMC POA&M rules

Use this sequence to decide how much you will rely on a POA&M.

  • Score yourself against all 110 requirements using assessment objectives
  • Fix every requirement that cannot be deferred, starting with the system security plan
  • Fix the higher-value requirements
  • Place only eligible, low-value gaps on the POA&M
  • Keep the total score comfortably above 88
  • Schedule all fixes well inside 180 days
  • Keep evidence for each closed item
  • Re-score and update the SPRS entry when items close

Cost and effort

A POA&M can reduce the upfront cost of an assessment, but it does not reduce the total cost, because the work is still needed. See CMMC Level 2 certification cost for a typical range and CMMC vs NIST 800-171 for how the program relates to the underlying standard. If your business handles only federal contract information, check CMMC Level 1, where POA&Ms are not permitted, and for the highest tier see CMMC Level 3.

Templates for POA&M and gap tracking

The working documents are a POA&M register, an internal scoring workbook, an SSP and closeout evidence files. The CMMC Toolkit includes editable templates for these, so your team can start from a consistent structure. The standard behind the requirements is explained on our NIST SP 800-171 page.

For a short summary of the 2026 requirements and updates, see the Smithers summary of CMMC Level 2 requirements and 2026 updates. Templates do not replace real controls, and assessors will test your claims against evidence.

An example of how CMMC POA&M rules affect a score

Suppose a contractor self-scores 91 out of 110 and has three gaps: a one-point logging requirement, a one-point awareness training item and a one-point media marking procedure. All three are low value and plausibly eligible, so the contractor could list them on a POA&M and still remain above 88. Now suppose a five-point multi-factor authentication gap appears during the review. That single gap pulls the score down and, because of its weight, is not something the contractor can defer, so it must be fixed before the assessment. Numbers here are illustrative, but the pattern is real: the heaviest items decide whether you can rely on the plan at all.

Governance for the CMMC POA&M rules

Assign one owner for the POA&M and review it every two weeks. Report open items, overdue items and the current score to an executive sponsor each month. Keep a change log so that every update to a date, owner or status is traceable, and require evidence before any row is marked closed. These habits make the CMMC POA&M rules manageable and give assessors confidence that you are managing gaps deliberately, not hoping they go unnoticed.

Using the POA&M as a management tool

A good register also helps you budget. Sum the estimated cost and effort for each open row, group the work by team and use the totals to request funding. Show leadership which items carry the most points and the most risk, and explain which fixes unlock the largest gain. When the suspended timeline resumes, you will be ready, and in the meantime you are reducing real risk to the information you handle.

Common mistakes with the CMMC POA&M rules

Common mistakes include assuming any control can be deferred, scoring yourself generously, letting target dates drift past the window, leaving the plan out of sync with the POA&M and the SPRS score and ignoring closeout logistics. Another is treating the suspended phase as a reason to stop work; the requirements in your contracts and the threats to your data have not gone away.

CMMC POA&M Rules FAQ

What score do I need to use a POA&M?

Published summaries report at least 88 of 110 points for Level 2. Confirm against the current rule and scoring methodology.

How long do I have to close POA&M items?

Reported as 180 days for remediation after an assessment resulting in conditional status.

Can I defer the system security plan?

No. Commentary reports that the system security plan requirement cannot be placed on a POA&M.

Are POA&Ms allowed at Level 1?

No. Reporting indicates that Level 1 does not allow POA&Ms.

Is Phase 2 still on for November 2026?

A defense compliance publication reports that the phase was suspended on 13 July 2026 with no replacement date announced as of late September 2026. Confirm current status and your contract terms.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.